Documentation
DocsAPI reference

Permissions

Every permission a role can carry, grouped by area, with who can hold it and the endpoints that require it.

Updated Sep 22, 2026

Organization

PermissionDescriptionHeld byUsed by
organization.deleteDangerousSchedule the organization for deletionPeople, api_keyNo published endpoint
organization.readRead organization settings and policyPeople, api_key, organization_api_keyNo published endpoint
organization.settings.writeChange organization settings and policyPeople, api_keyNo published endpoint

Membership

PermissionDescriptionHeld byUsed by
membership.inviteInvite people and manage pending invitationsPeople, api_key
membership.readList members and pending invitationsPeople, api_key, organization_api_key
membership.writeSuspend, reactivate, and remove membersPeople, api_key

Team

PermissionDescriptionHeld byUsed by
team.escalation.activateActivate, roll back, and deactivate team escalation policiesPeople, api_key, organization_api_key
team.escalation.writeCreate team escalation policy revisionsPeople, api_key, organization_api_key
team.member.writeChange who is on a teamPeople, api_key
team.readList teams and their rostersPeople, api_key, organization_api_key
team.writeCreate, rename, and archive teamsPeople, api_key

Agent

PermissionDescriptionHeld byUsed by
agent.credential.issueDangerousIssue instance credentials and provisioner tokensPeople, api_key, organization_api_key
agent.credential.revokeRevoke instance credentials and provisioner tokensPeople, api_key, organization_api_key
agent.readView agents, their instances, and credential statePeople, api_key, organization_api_key
agent.writeCreate agents and change their statusPeople, api_key, organization_api_key

Pipeline

Escalation path

Request

PermissionDescriptionHeld byUsed by
request.claimClaim a pending request while reviewing itPeople, api_key
request.createCreate approval requestsAgents
request.decideApprove or deny requests routed to youPeople, api_key
request.decide.unroutedDangerousDecide requests that were routed to other people (break glass)People, api_keyNo published endpoint
request.readRead approval requests and their outcomesPeople, api_key, organization_api_key, Agents
request.read.unroutedRead requests that were routed to other people, whatever the visibility policyPeople, api_key, organization_api_keyNo published endpoint

Gateway

PermissionDescriptionHeld byUsed by
gateway.callHosted editionRelay tool calls through the MCP gatewayGatewayNo published endpoint
gateway.readHosted editionView MCP gateway servers and credentialsPeople, api_key, organization_api_key
gateway.writeHosted editionConfigure MCP gateway servers and credentialsPeople, api_key, organization_api_key

Webhook

Connection

PermissionDescriptionHeld byUsed by
connection.readView SSO, directory, chat, and domain connectionsPeople, api_keyNo published endpoint
connection.writeDangerousConnect and disconnect SSO, directories, chat apps, and domainsPeople, api_keyNo published endpoint

Audit

PermissionDescriptionHeld byUsed by
audit.readHosted editionRead the audit logPeople, api_key, organization_api_key

Api key

PermissionDescriptionHeld byUsed by
api_key.issueMint personal API keys and manage your ownPeople
api_key.readList every API key in the organizationPeople
api_key.revokeRevoke any API key in the organizationPeople
api_key.organization.issueDangerousHosted editionIssue organization API keysPeople

Permission policy